Skip to content

Leadership1 publisher2 min readPublished

NIST is revising its AI risk management framework

NIST's own page says a revised AI RMF is in progress. The notice sits above the 2023 Core excerpt, and its four functions and subcategory numbering are what internal policies, audit files and vendor attestations quote.

The Board Room · Leadership desk

What happened

  • The 2023 Core divides govern, map, measure and manage into categories and subcategories, which are themselves subdivided into specific actions and outcomes.
  • The framework leaves users to decide which categories and subcategories they apply, and says its actions are not a checklist or an ordered set of steps.
  • NIST did not say when the revision will land or what will change, and has not published a draft of the revised framework.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • constraint If the revision renumbers categories or subcategories, every control matrix, audit workpaper and questionnaire that points at 1.0 identifiers has to be re-keyed. That work falls on whoever maintains the crosswalk.
  • decision Without a published date, waiting for the revised text is not a plan with an end. A program has to choose now between freezing its artifacts against 1.0 and keeping them loose enough to re-point later.
  • exposure An attestation that claims alignment to the NIST AI RMF without naming a version becomes ambiguous the day two versions exist. Resolving it falls to the customer holding the contract.
  • precedent Because the framework leaves selection and ordering to the adopter, the revision on its own sets no deadline; a deadline only arrives when a regulator or a buyer cites a particular version.

NIST's notice is two sentences: "The AI RMF 1.0 is being updated. A revised version is in progress." They sit above an excerpt labelled as coming from the 2023 framework, which is what the page still serves to anyone writing policy this week.

Governance paperwork rarely attaches to the four function names. It attaches a level down, where the Core breaks each function into categories and subcategories, and those into specific actions and outcomes. A policy that quotes govern, map, measure and manage survives a renumbering intact; a control matrix keyed to subcategory identifiers does not.

The 2023 text also limits how much a revision can strand. Some organizations select from among the categories and subcategories; others apply all of them, and NIST writes that the actions "do not constitute a checklist, nor are they necessarily an ordered set of steps". Once govern is instituted, most users would start with map and continue to measure or manage, though the functions may be performed in any order. The Playbook that supplies suggested tactical actions is voluntary as well, and both it and the framework sit in NIST's Trustworthy and Responsible AI Resource Center.

On this record, the revision of a voluntary framework is close to a documentation exercise. The cost appears where the version number was never written down. An attestation saying a vendor is aligned to the NIST AI RMF answers to one document today and to two after the revised version publishes. The party holding the contract is the one who has to ask which.

The govern function is where a rewrite would be felt first outside the compliance team. In 1.0 it is cross-cutting, infused throughout AI risk management, with compliance and evaluation aspects integrated into each of the other functions. It also addresses the full product lifecycle, including legal issues concerning third-party software or hardware systems and data. If the revision touches that language, the edit lands in supplier questionnaires.

Nothing expires this quarter, and the choice in front of a program is narrow: whether each artifact records the framework version and the subcategory it answers to. With both recorded, a version swap later is an edit to one column instead of a rereading of every policy.

What to watch

  • Publication of a draft or concept paper for the revised AI RMF, and whether the 1.0 subcategory numbering carries over into it.
  • Whether the Playbook is revised alongside the framework or trails it, leaving tactical actions keyed to the older text.
  • Whether customer contracts and supplier questionnaires start naming a specific AI RMF version and date instead of the framework generically.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories